Binance Warns One Wrong Copy-Paste Can Send Crypto to an Address-Poisoning Scammer
• September 6, 2026 11:21 pm • CommentsA crypto wallet can be perfectly secure and still send money straight to a scammer.
That is the danger behind address poisoning, a low-cost trick that turns a wallet’s own transaction history into bait. The attacker does not need to break the wallet or learn its seed phrase.
Instead, the scammer creates an address that resembles one the victim has used before. A tiny transfer then plants that lookalike in the visible history, waiting for the user to copy it during a later payment.
Binance Academy explains that the trap works because long hexadecimal addresses are hard to compare at a glance. Attackers often mimic the opening and closing characters people are most likely to check.
The attacker can then send a zero-value token transfer or a tiny amount from the lookalike address. That transaction places the poisoned destination beside legitimate activity without requiring the victim to approve a contract or visit a phishing page.
The history entry is only preparation; the loss occurs if the victim later copies it as a trusted destination. Because blockchain transfers are irreversible, the attacker needs just one rushed repeat payment to succeed.
Binance’s recommended defenses focus on breaking that sequence before the final transfer. Users should rely on verified address-book entries, inspect more than a few leading and trailing characters, and use test transactions when the amount is meaningful.
Binance renewed that warning Sunday:
Not every crypto scam involves hacking your wallet. ⚠️
Address poisoning attacks rely on lookalike wallet addresses appearing in your transaction history, hoping you'll copy the wrong one.
Learn how to stay protected 👇https://t.co/R8jLMsSApk
— Binance (@binance) September 6, 2026
The attack is especially dangerous for people who make repeat transfers to exchanges, business wallets or cold storage. Familiarity can become the weakness because the destination appears to be one the user already trusts.
The safest habit is simple: never copy a destination from transaction history. Use a verified address book, a fresh deposit page from the official service, or another trusted source every time.
Checking only the first and last four characters is not enough when the attacker deliberately chose those characters to match. Compare the full address or use a wallet that clearly identifies saved, verified destinations.
For a large transfer, send a small test amount first and confirm receipt through a separate trusted channel. That adds one more step, but blockchain settlement offers no chargeback after a poisoned address receives the funds.
Address poisoning is not the only risk that can remain hidden long after a wallet interaction. Old token approvals may continue giving a smart contract permission to move assets months or years after the user has forgotten the original transaction.
Scam Sniffer reported this week that two Ethereum wallets lost a combined $187,046 after phishing approvals signed in 2024 were never revoked. In one case described by the security service, funds arrived in the wallet and were drained 25 hours later.
The cases involve a different mechanism from address poisoning, but the lesson is related: what appears in a wallet’s history can create risk long after the original activity.
🚨 Two wallets just lost $187,046 on Ethereum. The phishing approvals: signed back in 2024. Never revoked.
$124,563 in SYN: approval signed Feb 2024, funds arrived Aug 30, drained 25 hours later.
victim: 0x686618abb3730079601a5abead6ec24549c5ce34
tx: https://t.co/TiURJ5XUZ3… pic.twitter.com/lXa3NceFTH— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) September 1, 2026
Users should review active token approvals with a reputable explorer or wallet tool and revoke permissions they no longer need. They should also verify the tool itself through an official project or explorer domain before connecting a wallet.
No single check covers both threats. Full-address verification protects the destination before a transfer, while approval reviews reduce permissions that an attacker may exploit later.
The common defense is refusing to treat wallet history as proof of trust. A familiar-looking entry is only a record that something happened, not evidence that the destination or permission is still safe.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
